ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

CrowdStrike investigates FalconFlank privilege escalation report

An anonymous researcher called Nightmare Eclipse said FalconFlank could abuse CrowdStrike Falcon on current Windows systems, while CrowdStrike said it was investigating and told customers to change a policy setting.

BleepingComputer

Nightmare Eclipse released FalconFlank and said it was a zero-day privilege-escalation exploit for CrowdStrike Falcon. The researcher said it worked on current Windows 11 25H2 and Windows Server 2025 systems and could let an attacker gain SYSTEM access by abusing Falcon's remediation feature for malicious Office macros.

When BleepingComputer asked CrowdStrike for more detail, a spokesperson said the company was investigating the claims. The spokesperson advised customers to disable the Microsoft Office Windows policy setting that controls File Suspicious Macro Removal, said customers still had protection through Cloud Anti-malware for Microsoft Office Files, and pointed readers to a FalconFlank tech alert that was only available through CrowdStrike's support portal.

This week Nightmare Eclipse also released privilege-escalation exploits for Kaspersky Antivirus for Endpoint and GenDigital's Avast Antivirus, together with a denial-of-service exploit for Nvidia called GreenSection. Kevin Beaumont said on Thursday that the privilege-escalation exploits released this week were real and worked.

Nightmare Eclipse had also disclosed several Microsoft zero-days since April, covering Microsoft Defender, BitLocker and other Windows components. Microsoft said after the first disclosures that it might take legal action against people involved in malicious activity that harmed customers, and some of the named flaws had since been fixed while others still awaited patches.

Named in this story

People

Nightmare Eclipse
the anonymous researcher who released FalconFlank and other exploits
Kevin Beaumont
the security expert who said the week's privilege-escalation exploits worked

Companies

CrowdStrike
said it was investigating the claims and advised customers on a setting change
Microsoft
the vendor that had multiple zero-days disclosed against its products and warned about legal action
Nvidia
the vendor whose systems were said to be hit by a crash bug

Products and systems

FalconFlank
the named zero-day privilege-escalation exploit
CrowdStrike Falcon
the endpoint security platform FalconFlank targeted
Windows 11
one of the Windows versions said to be affected
Windows Server 2025
one of the server versions said to be affected
Kaspersky Antivirus for Endpoint
one of the products targeted by Nightmare Eclipse
HardBreacher
the privilege-escalation exploit released for Kaspersky
Avast Antivirus
GenDigital's antivirus product targeted by another exploit
PrettyPrague
the privilege-escalation exploit released for Avast
GreenSection
the denial-of-service exploit released for Nvidia
LegacyHive
one of the Microsoft zero-days disclosed since April
RoguePlanet
one of the Microsoft zero-days disclosed since April
YellowKey
one of the Microsoft zero-days disclosed since April
GreenPlasma
one of the Microsoft zero-days disclosed since April
MiniPlasma
one of the Microsoft zero-days disclosed since April
UnDefend
one of the Microsoft zero-days disclosed since April

How the source tells it

The article read as brisk and threat-focused, with alarm from SYSTEM-level impact, urgency from active vendor response, and novelty from a run of newly named exploits.

  • alarm the consequences were framed around SYSTEM-level access and a system crash
  • novelty a cluster of newly named zero-days and exploit labels gave the piece a fresh-wave feel
  • urgency live investigation and immediate mitigation advice were emphasised as the story unfolded